WordPress.org verlangt ab Oktober 2FA für Plugin-Entwickler

Teilen:

Starting October 1st, WordPress.org accounts that can push updates and changes to plugins and themes will be required to activate two-factor authentication (2FA) on their accounts.

The decision is part of the platform’s plugin review team effort to reduce the risk of unauthorized access, which could lead to supply-chain attacks.

“Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress sites worldwide,” reads the announcement.

“Securing these accounts is essential to preventing unauthorized access and maintaining the security and trust of the WordPress.org community.”

WordPress is an open-source content management system (CMS), blog tool, and publishing platform that helps users create and manage websites.

Users have access to a wide variety of free and paid themes and plugins that allow customizing the look and extending the functionality of their websites.

A malicious actor hijacking a publisher’s account could alter code in a theme or plugin to include vulnerabilities or backdoors that would allow privileged access to websites using them.

2FA and SVN passwords

ADVERTISING

To prevent such risks, the 2FA security feature needs to be active on October 1st for accounts that have commit access on the WordPress.org platform. Account administrators can enable the setting from the security menu of their account. Step-by-step instructions on how to activate 2FA are available here.

Additionally, WordPress.org has added SVN-specific passwords that separates the access to making code changes from the main account credentials.

Plugin authors using deployment scripts such as GitHub Actions will need to update their scripts to use the new SVN-specific passwords. Check this page for more information on Subversion (SVN) access.

The team notes that technical limitations prevent 2FA from being applied to existing code repositories and opted to combine “account-level two-factor authentication, high-entropy SVN passwords, and other deploy-time security features.”

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:04 pm, Juni 22, 2025
Wetter-Symbol 21°C
L: 21° | H: 22°
wenige Wolken
Luftfeuchtigkeit: 64 %
Druck: 1011 mb
Wind: 19 mph SW
Windböe: 32 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 10 mph 63 % 1011 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.66 mm 66% 14 mph 82 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
13° | 24°°C 0.2 mm 20% 14 mph 81 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 88 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 15 mph 84 % 1018 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 10 mph 63 % 1011 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 13 mph 73 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0.66 mm 66% 14 mph 82 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 13 mph 45 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 13 mph 32 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 40 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€86,436.76
-3.17%
Ethereum(ETH)
€1,898.08
-8.57%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.71
-5.34%
Solana(SOL)
€112.76
-6.01%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.129400
-5.85%
Shiba Inu(SHIB)
€0.000009
-5.85%
Pepe(PEPE)
€0.000008
-8.84%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen